<p>For studying intrusion detection data we consider data points referring to individual IP addresses and their connections. We build networks represented by graphs associated with those data points, such that vertices in a graph are constructed to denote the respective IP addresses, with the key property that attacked data points are part of the structure of the network. More precisely, this paper proposes a novel approach using simplicial complexes to model the desired network and the respective intrusions in terms of simplicial attributes, thus generalizing previous graph-based approaches. Applying adapted network centrality measures related to simplicial complexes yields patterns associated to vertices, which themselves contain a set of features. These are used to describe the attacked or the attacker vertices, respectively. Comparing this new strategy with classical concepts demonstrates the advantages of the presented approach using simplicial features for detecting and characterizing intrusions.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Simplicial complexes in network intrusion profiling: pattern construction through simplicial centralities

  • Mandala von Westenholz,
  • Martin Atzmueller,
  • Tim Römer

摘要

For studying intrusion detection data we consider data points referring to individual IP addresses and their connections. We build networks represented by graphs associated with those data points, such that vertices in a graph are constructed to denote the respective IP addresses, with the key property that attacked data points are part of the structure of the network. More precisely, this paper proposes a novel approach using simplicial complexes to model the desired network and the respective intrusions in terms of simplicial attributes, thus generalizing previous graph-based approaches. Applying adapted network centrality measures related to simplicial complexes yields patterns associated to vertices, which themselves contain a set of features. These are used to describe the attacked or the attacker vertices, respectively. Comparing this new strategy with classical concepts demonstrates the advantages of the presented approach using simplicial features for detecting and characterizing intrusions.